Key system API
Read and change a project's free-key page: its settings, steps, funnel, visits and blocked accounts.
A project's free-key page (luaward.com/k/…) hands out time-limited keys after a visitor does the steps you set. These routes read it and change what is safe to change from a program. Changing needs a key with the keysystem:write scope (Full access has it). To make a temporary key yourself, make an ordinary key with key_days.
Read
GET /v3/projects/:id/key-systems
Returns key_systems. GET …/key-systems/:key_system_id returns one with its steps, in order. A key system has key_system_id, name, slug, page_url, project_id, script_id (the script whose loadstring the page shows), enabled, key_hours, max_keys_per_visitor, allow_extending, allow_forgetting, require_discord, block_vpn, blocked_countries, session_timeout_seconds, enforce_ip_match, steps, created_at and updated_at. A step has step_id, position, title, provider, target_url, required_seconds and active. One that is not in this project answers 404 KEY_SYSTEM_NOT_FOUND.
Change settings
PATCH /v3/projects/:id/key-systems/:key_system_id
| Field | Rule |
|---|---|
| name | 1 to 80 characters. |
| enabled, allow_extending, allow_forgetting, require_discord, block_vpn, enforce_ip_match | true or false. |
| key_hours | How long a key lasts: 0.25 to 8760 hours. |
| max_keys_per_visitor | 1 to 20. |
| blocked_countries | Up to 250 two-letter codes in capitals, such as RU. |
| session_timeout_seconds | 300 to 86400. |
| script_id | A live script of the same project, or null to show none. |
At least one field; the same limits as the dashboard. The answer is the updated key_system. The slug, the page's look and the steps' provider and link are changed in the dashboard.
PATCH /v3/projects/:id/key-systems/:key_system_id/steps/:step_id
active, required_seconds (0 to 600, the shortest time the step may take) and title, at least one. Anything else in the body is ignored.
Funnel, visits and blocks
GET /v3/projects/:id/key-systems/:key_system_id/stats
days is 7 (default) or 30. The answer has the funnel (visit, start, step, complete, claim, block), countries and blocked_because (why visitors were turned away: vpn, country, captcha, bypass, discord, limit).
GET /v3/projects/:id/key-systems/:key_system_id/visits
The latest visits, newest first: limit (1 to 100, default 30) and before (the next_before of the previous page, a timestamp). Each has visit_id, status, step, country, browser, vpn, discord_id, started_at and finished_at. A visitor's address and browser id are never part of it.
GET /v3/projects/:id/key-systems/:key_system_id/blocks
The accounts and addresses the page turns away: block_id, kind (discord, ip or visitor), value and reason. An address or a browser is kept only as a hash, so only its first eight characters are shown. POST …/blocks with discord_id (15 to 22 digits) and an optional reason blocks a Discord account (201 with block_id; 409 ALREADY_BLOCKED if it already is). DELETE …/blocks/:block_id lifts one (404 BLOCK_NOT_FOUND if there is none). Blocking an address is done in the dashboard.